Disaster Recovery - Business Continuity Planning Audits

The internal auditor can play a critical role in disaster recovery/business continuity resumption planning within an organization. This page provides resources and articles on the subject that you can use for reviews and planning for audits in this area. If you have any resources including audit programs, internal control questionnaires, checklists or other documents please consider sharing them for the benefit of the global audit community. Send your documents as attachments to editor@auditnet.org

Thanks to Dan Swanson for his contributions to this page.

 


EXECUTIVE GUIDE: DISASTER RECOVERY | SearchCIO.com

The devastating effects of hurricanes Katrina and Rita last fall made clear the importance of disaster recovery plans perhaps as well or better than any other

events in recent history. This Executive Guide offers news, advice and other
resources to help CIOs prepare their organizations for the worst.
 
Boardroom Briefing: Business Continuity and Disaster Recovery
 
The Canadian Center for Emergency Preparedness (CCEP)
Two leading BCP and DR resource “portals”
The Business Continuity Institute (BCI) offers free documents online to help practitioners implement effective business continuity plans. The BCI 76-page Good Practice Guidelines was originally prepared in 2002 by a working group with numerous business continuity planning (BCP) experts; it was then rewritten to take into account numerous comments, new public standards and recent legislation.

Business Continuity and Auditing Business Continuity

Leading guidance from OGC (Office of Government Commerce) in the UK
FFIEC Business Continuity Planning Booklet
 

The IIA’s DR and BCP resource repository

Is Your Organization's Business Continuity Plan Effective? - Identifying key problem areas during audits of business continuity plans can enhance an organization's disaster recovery efforts and ensure the quick return of business activities and services.
 
Assessing the Effectiveness of a Contingency Plan for an Individual Business Unit

ISACA global Knowledge Network - Using the search facility (at the link provided) enter “business continuity”, “disaster recovery”, “emergency management”, etc, to obtain a variety of resources to help your efforts.

 
All-Hands.net is a user-supported community where emergency management, homeland security, and business continuity professionals come together to post articles, share files, and communicate with others in our profession.

Generally Accepted Business Continuity Practices – includes information on:

  1. Project Initiation and Management
  2. Risk Evaluation and Control
  3. Business Impact Analysis
  4. Developing Business Continuity Strategies
  5. Emergency Response and Operations
  6. Developing Business Continuity
  7. Training and Awareness
  8. Maintaining and Exercising Business Continuity Plans
  9. Public Relations and Crisis Communications
  10. Coordination with Public
 

BS 25999 Business Continuity Management - a resource for information, links, news, events, resources and discussion for those seeking information and guidance on BS25999 specifically, also business continuity and emergency management in general.

Business Continuity Planning and the Avian Flu

 
A Community Risk Register - Each local resilience forum area in the UK has to provide a public Community Risk Register. This document is one of only a few that is being reviewed by central government in the UK as a contender for best practice of the publication of generic risk assessments in a local area. It was very much a multi-agency effort with over 80 contributors from at least 20 agencies.

Computer Room Emergency - Only a Matter of Time

DRJ’s Disaster Recovery World Online
Availability resources by NoticeBored

Disaster Recovery Audit and Planning - Introduction to the subject of disaster recovery planning.

 The Internal Auditor's Role in Disaster Recovery - article from the American Association of State Compensation Insurance Funds.

Disaster Recovery Guidelines from Bankers Online

Disaster Recovery and Business Resumption Planning article by Dana Turner from Bankers Online

Internal Audit’s perspective on the Continuity Plan Policy and a possible approach to focus development of an acceptable recovery plan is a PowerPoint presentation by the University of Minnesota's Internal Audit group. 

Maintaining and Exercising Business Continuity Plans - from the Disaster Recovery Institute Canada 

Selecting the "Right" Business Continuity Planning Recovery Strategy from ISACA

Audit Programs, Internal Control Questionnaires and Checklists

  1. Backup Procedures and Disaster Recovery Audit Program

  2. Business Continuity Disaster Recovery Management

  3. Disaster Recovery Plan
  4. Disaster Recovery - Business Resumption Audit Program (Word, pdf)
  5. Disaster Recovery - Contingency Planning Audit Program
  6. Disaster Recovery - Contingency Planning ICQ
  7. Disaster Recovery Risk Evaluation (Word (pdf)

Miscellaneous Resources Contributed by AuditNet Community Members

  1. Bell South Business Continuity Planning Guide
  2. Business Impact Analysis Survey from NC State
  3. Business Continuity Report Benchmark Study
  4. Considerations by Executive Management
  5. Continuity Terminology Matrix
  6. Disaster Recovery Plan
  7. Earthquake Calendar Sender
  8. Earthquake Calendar Tri-Sender
  9. FEMA Emergency Management Guide
  10. Glossary of BCP Terms
  11. Incident Management Checklist
  12. Information Security Checklist
  13. NASD Notice Business Continuity Plans
  14. Securities Industries Association BCP Best Practices
  15. What Does it Take to Build a Good Business Continuity Plan?